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16 May 2013 


MEMORANDUM FOR THE CHAIRMAN. INTELLIGENCE OVERSIGH T BOARD 

THRU: Assistant to the Secretary of Defense (Intelligence Oversight) 

SUBJECT: (U//TOUO) Report to the Intelligence Oversight Board on NSA Activities - 
INFORMATION MEMORANDUM 

(U/ /FOUO) Except as previously reported to you or the President or otherwise stated in the 
enclosure, we have no reason to believe that intelligence activities of the National Security Agency during 
the quarter ending 31 March 2013 were unlawful or contrary to Executive Order or Presidential Directive 
and, thus, should have been reported pursuant to Section 1.6(c) of Executive Order 12333, as amended. 

(U//F QUO) - The Inspector General and the General Counsel continue to exercise oversight of 
Agency activities by inspections, surveys, training, review of directives and guidelines, and advice and 
counsel. 

JCmu eOPtuJL 

DR. GEORGE ELLARD 
Inspector General 

RAJESH DE 
General Counsel 


(U//FOUO) 1 concur in the report of the Inspector General and the General Counsel and hereby 
make it our combined report. 

KEITH B. ALEXANDER 
General, U. S. Army 
Director, NSA/Chief, CSS 
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(U) REPORT TO THE INTELLIGENCE OVERSIGHT BOARD ON NSA ACTIVITIES 

FIRST QUARTER CY2013 


(U/ /FOUO) Pursuant to Executive Order 12333 (E.O. 12333). as amended. National 
Security Directive No. 42. and other legal and policy directives, the National Security Agency 
(NSA/Agency) conducts signals intelligence (S1GINT) and information assurance (IA) activities 
on behalf of the US. government. NSA's S1GINT and IA operations, as well as activities in 
support of those operations, might result in the acquisition of non-public information about or 
concerning U.S. persons (USPs). Agency personnel are required to follow procedures designed 
to protect USP privacy, consistent with the Fourth Amendment to the U.S. Constitution and other 
law. NSA has also established internal management controls to provide reasonable assurance 
that NSA personnel are complying with procedures for handling USP information, such as 
minimization procedures adopted by the Attorney General (AG) and approved by the Foreign 
Intelligence Surveillance Court (FISC) to govern USP information acquired during SIGINT 
operations conducted pursuant to the Foreign Intelligence Surveillance Act (FISA) of 1978. as 
amended. This report summarizes incidents of non-compliance with NSA's USP procedures, as 
well as other matters required to be reported to the Intelligence Oversight Board, that were 
identified during the first quarter of CY2013. 


I. (U) SIGINT Incidents 


(U//F OUQ) Section 1.7(c)(1) ofE.O. 12333 authorizes NSA to collect (including through 
clandestine means), process, analyze, produce, and disseminate SIGINT data for foreign 
intelligence and counterintelligence purposes to support national and military missions. 

However. FISA regulates the intentional acquisition of communications to or from unconsenting 
USPs. wherever such persons may be located, and also regulates certain collection techniques, 
particularly techniques used against persons located inside the United States. As a result. NSA 
personnel distinguish between E.O. 12333 SIGINT operations and activities that NSA conducts 
pursuant to FISA authorizations. 


I.A. (U) E.O. 12333 SIGINT Incidents 


i(b) (1) 

(b)(3)-P.L. 


86-36 


(S//SI//NF) During the reporting period. NSA determined that □ incident reports 
indicated non-compliance with AG-approved procedures in Department of Defense (DoD) 
Regulation 5240.1-R. including the regulation's Classified Annex, as well as incidents of non- 
compliance with internal control procedures that govern NSA's acquisition, processing, 
retention, a nd dissemina tion of USP information acquired during E.O. 12333 SIGINT 
operations. I ~1 incidents involved acquisition errors, such as the mistaken or inadvertent 

targeting of a USP; | | concerned improper queries of NSA raw SIGINT databases 

(unminimized and unevaluated for foreign intelligence), such as queries that were overly broad 
or not reasonably designed to restrict the return of non-pertinent or unauthorized USP 
information or were performed without first conducting the necessary research; 


involved unauthorized access to or improper handling of raw SIGINT data; and | | involved 


Classified By: 


1 ) 

3)-P.L. 86-36 
3)-50 USC 3024(i) 


Derived From: NS A/CSS M 1-52 
Dated: 20070108 
Declassify On: 20380501 


T OP SECRET//31/TK//NOTORN 


(b)(3)-P.L. 86-36 
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(b)(1) 

(b)(3)-P.L. 86-36 


system errors. In light of the scope and scale ofNSA’s E.O. 12333 SIGINT operations _ 

e-mail addresses, telephone numbers, and other "‘selectors” were tasked for E.O. 12333 SIGINT 
(bj (i) collection during the reporting period), the overall error rate was extremely low. 

(b) (3)-P. L. 86-36. . 

(b) (3)-50 use 302 (Sm,RCL TO UQA. rVEY) ! 


(U//F0fcJOTThe vast majority of E .O 12333 incidents during the reporting period 
occurred because of human error and were addressed through remedial training of the 
responsible personnel. Noteworthy E.O. 12333 SIGINT incidents included the following: 

• (TS//S1//NF) During this quarter , the NSA Office of the I nspector General (OIG) learned 
that a data spillage had occurred !* | involving communications 

intelligence (COMINT). Appro ximately! |time-sensitive reports containing TOP 

SECRET COMINT information! 

I | the reports 

were available to personnel cleared only for SECRET information. All of the reports 
have been removed from the known locations, and a damage assessment is under way. 


database query ran against!_ 

analyst attempted to stop the query! 


auditor discover* 
(b) ( 3 ) -p. l. 86 -^ere returned. 


the error. 


selector that contained a typographical error. The 
~1 but did not follow the correct process. 

when the database 

_ No query results 


•(b) (1) 

(b)(3)-P.L. 86- 
(b) (3)-50 use 3 



(S//SI//RCL TO US A. fVEY) ! I an auditor discovered that an analyst 

had queried ! I selectors without performing the necessary foreignness checks. No 
results were returned, and no reports were issued. 


an analyst performed a query in a 


raw SIGINT database 


| | The query results were deleted, and no reports were issued, 

been suspended. 


'(b)(1) 

(b)(3)-P.L. 86-36 
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■ (S//SI//N P) 


it was discovered that a syste ms error mista kenly 


allowed selectors identified as USPs to be approved for tasking 


occurred. 


(TS//S1//NP) [ 


No. collection 

..'(b) (i) 

(ii) (3)-P.L. 86-36 


resulted in selectors | 

All selectors were detasked [| 


an analyst discovered a glitch in a tasking tool that 


J 


(TS//SI//NF) 


| it was discovered that| |selec torsj_ _ 1 


error in the configuration tiles 
(U/ / F QUO) [ 


~jall improp erly routed data was deleted. An 
T caused the incident. 


it was discovered that a file containing raw SIGINT 
(b)(3)-P.L. 86-36 j ia( j been uploaded into a repository that unauthorized personnel could have accessed 

'(b) (1) 

(is) (3) -P. L. 86-36 

I an analyst discovered collection acquired during a 


The file was deleted. 


-fFSrfSTTTNn[ 


target's visit to the United States from a selector 


The incident was isolated to a particular 


(TS.'/SI/TK/. ' RCL TO UP A. fY E V lf 


(bid). 

(b)(3)-P.L. 86- 
(b) (3)-50 USC 3| 


Purging of the collected data was completed |_ 


(T3//3 I //RCL TO USA. rVCY) 
determined to be associated with a USP^ 


~1 it was discovered that a selector 


"bec ause of a 

Upon discovery of 


miscommumcation 

the incident, the analyst immediately stopped the query and deleted the results. 1(b) (i) 

1-“Ti (b) (3) -P. L. 86-36 

(3//REL TO USA, f _ ---- Iwas 

discovered to have been conducting SIGINT without proper authority 
conducted an unapproved collection exercise. 


]did not understand the 


importance of obtaining the proper legal authority for conducting SIGINT exercis es 
before | | Moreover, the Program Manager f | had 


been fielding it to| 


1 without the kno wledge or oversigh t of the 
jat Fort Meade. | | is contacting | 


Jas currently possessing SIGINT systems or scheduled to receive a SIGINT 


system in the near future to make them aware of SIGINT oversight requirements. 


I OP SLL RL T //SI/TK/AOFQRN 
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I.B. (U) FISA Incidents 


(b) (1) 

(b)(3)-P.L. 86-36 


■(G/VOL/NF) - During the reporting period, the Department of Justice (DOJ) filed | [notices 
with the FISC concerning incidents of non-compliance with authorizations issued to NSA 
pursuant to FISA, including incidents of no n-compliance with NSA's Court-approved FISA 
minimization procedures. The re w ere l I incidents of non-compliance with NSA internal 

control procedures. A total of I I of the incidents involved acquisition errors, such as the 

delayed detasking of targets; | [concerned improper queries of NSA raw SIGINT databases, 
such as queries that were overly broad or not reasonably designed to restrict the return of non¬ 
pertinent or unauthorized USP inf ormati on; ^involved unauthorized access to or improper 
handling of raw SIGINT data; and I I involved systems errors. (Some incidents might cause 
more than one notice to DOJ. and some notices did not involve incidents. Consequently, the 
number of notices does not correspond to the number of incidents.) 


(U// FOUO) The vast majority of FISA incidents during the reporting period occurred 
because of human error and were addressed through remedial training of the responsible 
personnel. Noteworthy FISA incidents included: Kb) (D 

(b) (3)-P.L. 86-36 

I.B.I. (U//F0F+0) NSA/CSS Title I FISA (b)(3)-50 use 3024 (i) 



communication to or from these numbers was acquired. 




(b)(3)-50 USC 3024(i) 
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(b) (1) 

(b) (3)-P.L. 86-36 
(b) (3)-50 USC 3024(i) 


"mm 

(b)(3)- 
(b) (3) - 


Wii 

(b) (3 


the non-compliant data was marked for purging, and no reporting occurred. 
(S//SI//NF) | ~ it was discovered that tiles possibly contai ning 

information acquired pursuant to FISA had been inadvertently placed on m 


All of 


(b)(1) 

(b)(3)-P.L. 86-36 


Upon discovery, all files were deleted 







A final notice on the matter was filed with the FISC 


SSSKSrtW (S/ i 'nCL TO I'SA. rVE V) 


(b) (1) 

(b)(3)-P.L. 86-36 


(S//S1//REL TO USA. FVEV ) 
query of identifiers provided to NSA by I 


an analyst executed 


connections. | 

identities against its collection and reports to|_ 


When the NSA analyst executed the query, he was unaware 


jwith a high risk of terrorist 
S lSA queries non-USP 
| results of those queries. 


query | 

otherwise used. 


NSA deleted the results from the 
Jand confirmed that the results had not been disseminated or 


(TB//BI/ /RCL TO U SA. PVE TT 
without r 


N SA discove red t hatj janalysts 

training might have been able to seef I data I I 


Although ncj 


data was found in 


, pursuant to 

) -p.L. 86-^eaining. 


^authorization. The | analysts have since attended [ 


(b) (1) 

(b) (3)-P.L. 86-36 
(b)(3)-50 USC 3024(i) 


I.B.3. (T8//SI//NF ) Business Records (BR) Order 

4 - TS//SI//N F) | an NSA analyst executed a valid query in 

NSA’s BR repository using a reasonabl e articulable suspicio n-approved selector 
belonging to a USP currently subject to | ~| The analyst then sent the 

results of the query via an e-mail alias to personnel who did not have the required training 
to handle the BRdata. The analyst’s supervisor rectified the situation. 


TTS//Sl//Nn 


NSA technical personnel discovered that NSA 


had inadvertently retained files containing call detail records that exceeded the five-year 
retention period These records, which had been produced pursuant to the FISC’s 
Primary Orders, 


]The records were among those 


used in conn ection with a migration of call detail records to a new system in or about 

The call detail records could be accessed or used only by technical pe rsonnel 
who had received appropriate and adequate training. | NSA 


TOP SECRET//31/TK//NOrORN 
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technical personnel destroyed the call detail records used in the migration of records that 
had been retained past the five-year limit. 

I.B.4. (U) FISA Amendments Act (FAA) 

(TS SI RF L TO USA. F \ T 

occurred onl 


YT Onl I oc casions during t he first quarter, collection 
~^he United Statesl 


TT S//S1//R EL TO UP A. rV E¥»f 
distributed 


(b!(1) 

(b)(3)-P.L. 86- 



FAA §702 data was erroneously 


have been marked tor deletion from the repository. 

S//SI//RFI TOUS A FVEV -ll l it was discovered that NSA_ 

personnel ha d learned | It hat the user otl Iselector s had ! | 

]the United States[ I The selectors 


had inadvertently remained tasked 


All non-compliant data collected from 


has been marked for purging. No reports 


were issued. 


(TS//S1//REL TO USA. FVEY) 
selectors had been in correctly re-tasked under FAA §702 
without adjudication.^ 


NS A personnel discovered thatl I 



selectors were 


detasked upon discovery. All non-compliant FAA §702 data for each selector was 
marked for purging. . . (l) 

an NSA analyst erroneously tasked[ 


lb) 


3)-P.L. 86-36 


selectors without ascertain ing w hether the selectors were in the United States, Upon 
discovery of this error, the I " I selectors were emergency detasked and all non-compliant 
FAA §702 data for each selector was marked for purging. No reports were issued. 


(TS/ 51 RFL TOUSA. FVCY) [ 


technical error, caused by unknown c ircumstances 
the complete processing of] | files. NSA pro vides^ 


NSA discovered that a database 

had prevented 


taskimi. The 


1 for review tor all new FAA fr/02 
1 are the subject of theQ 
"database prevented certai 


under FAA targeting proc edures. The database prevented certain 

_ Jfrom being loaded int o ! I database. Another technical error (b)(3)-P.L. 86-36 

occurred| | also preventing £ I from being loaded into the 


database. After being alerted to the situation, the NSA database team loaded the missing 
| into the database[ 



rQP SECRET//GI/TK//NOrORN 


(b) (1) 

(b)(3)-P.L. 86-36 
(b)(3)-50 USC 3024(i) 
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'(b)(1) 

(b){3)-P.L. 86-36 
(b) (3)-50 USC 3024(i) 


(TS//S1//REL TO USA rv erlf 

request had been made[ 


__ it was discovered that a detasking 

I for a selector deemed to be no longer of interest. 


Further analysis revealed that thj | detaski ng request had not been carried out. 

The selector was | |in the United St ates ! I 

The selector w as detaskedl I All no n-compliant FAA §702 data 

collected from I | has been marked for purging. No 


reports were issued. 

(T! j , !jl „ RFL TQ U$A . FVEY } [ 


(b) (1) 

(b)(3)-P.L. 

it was discovered that between 


86-36 


_an analyst had e-mailed to as many as | | 

unauthorized analysts at a field location files containing data collected pursuant to 
FAA ^702. Upo n discovery of this incident, all sharing of raw SIGINT was stopped and 


on discovery or this incident, all sharing ot raw blullNl was stopped and 
|was instructed to purne the erroneously shared FAA §702 data fromQ ] 


■f T3//3l//REL TO USA. rYEY) | _| an analyst downloaded FAA §702 

data from a raw traffic repository and stored it in a local computer direct 017 that could be 
accessed by analysts who are not authorized for FAA §702 data. Upon discovery, the 
analyst moved the traffic to a directory where access can be limited to only analysts who 
are authorized for FAA §702 access. 


(TS//SI//REL TO USA. FVEV) During the week of 


a manager 


86-36 


discovered t hat FAA §702 traffic had been shared with an unauthorized analyst since the 
beginning ofl 


The sharing was halted[ 


and the 


analyst was instructed to return the FAA §702 data. Management reminded division 
personnel that the sharing of FAA §702 data with unauthorized personnel j&ppl) 

permitted. -- (b) (3)-P.L. 86-36 

l- 1 (b). (3)-50 USC 3024 (i) 

(TS//SI//REL TO USA. FVEY) |_|NSA discovered that an a nalyst 


[ 


without the proper FAA §702 training had the potential to see FAA §702 data 


removed from the 


The unauthorized user was 


until FAA §702 training is completed. 


(TS - S I RIM. TO USA. FVEV 


it was discovered that a file 


containing data collected under FAA §702 had not been restricted to allow only those 

trained for access to FAA §702 data. It is not known whether anyone without_ 

appropriat e training had accessed the file. The file permissions were changed [~ | (b)(1) 

to restrict access to only analysts who have completed appropriate FAA §702 ( b )(3)-P.L. 86-36 


training. 

I.C. (U) Dissemination ofU.S. Identities 


- fF ' S//Gl//Nr) The NS A/C SS enterprise issued | | SIGINT product reports during the 

first quarter ofCY2013. | | produc t reports incorrectly dissem inated USP information, and 
the reports were recalled asNSA/CSSl I analysts learned ofUSPs, 


TOP SECRE TtlSB IK77NOFOKN 
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U.S. organizations, or U S. entities named without authorization. All data in the recalled reports 
was deleted as required, and the reports were not re-issued or were re-issued with proper 
minimization. 


I.D. (IJ) Detection and Prevention of Violations 


/tb)(1) 

(b) (3)-P.L. 86-36 


(TS‘"S1 "Nf) NS A continues its process to identi fy when the users o f properly tasked 

process identified 


]the United States. NSA' 


in the first quarter. 


Collected data was purged from NSA/CSS's raw traffic repositories. NSA’s process for 




1 





|in the first quarter. In all 

cases, information acquired during the period 

uiiic niiropfl 


the United 


II. (U) IA Incidents 


(U/r TOU O) National Security Directive No. 42 and $ 1.7(c)(6) ofE.O. 12333 designate 
the Director ofNSA as the U.S. government's National Manager for National Security Systems. 
NSA’s Information Assurance (1A) responsibilit ies include authority for NSA to intercept 
encrypted or other official communications of U.S. Executive Branch entities or 
U.S. government contractors for communications security purposes; perform technical security 
countermeasure surveys to determine whether unauthorized electronic surveillance is being 
conducted against the United States; examine U.S. government national security systems and 
evaluate their vulnerability to foreign interception and exploitation; and assess the security 
posture of and disseminate information on threats to and vulnerabilities of national security 
systems. NSA's IA activities often result in the acquisition of non-public communications or 
other non-public information about or concerning USPs. 


(U/ /FOUO) During the reporting period. NSA identified ! l incidentsof non-compliance 
with the AG-approved procedures and NSA internal control procedures that govern the handling 
of USP information acquired during NSA's IA activities. The incidents were attributed to 
human error and were addressed through remedial training of the responsible personnel 
Noteworthy IA incidents included: (b)(3)-P L 86-36 


(U/ ZfOUO) 


an analyst released a tipper containing a hyperlink that 


provided recipients of the tipper tccess to a repository for analyzed Communications 
Security (COMSEC) data, e ven if the recipie nts lacked access creden tials. A hyperlink 
had been provided in | [ additional tippers | ~ All tippers have 

been recalled, and new procedures for issuing tippers have been established to prevent 
future occurrences. A security update has been developed to eliminate the bug that 
allowed the live link to function for those without authorized access to the COMSEC 
data. 


TUP SLCKLT77ST7T fftff sOTORN 
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111. (U) NSA/CSS OIG 10 Inspections, Investigations, and Special Studies 

(U//FOUO) During the first quarter ofCY2013. the OIG reviewed NSA/CSS intelligence 
activities to determine whether they had been conducted in accordance with statutes. E.O.s. AG- 
approved procedures, and DoD and internal directives. The problems uncovered were routine, 
and the reviews showed that operating elements understand the restrictions on NSA/CSS 
activities. 


(U) Joint Inspection: NSA/CSS Texas (NSAT) 


(S//REL-TO USA: 1 FVDY ) During the joint inspection of NSAT 


(b)(1) 


10 inspectors reviewed 10 program management. 10 training for site (b)(3)-P-L. 86-36 


personnel, and application of 10 standards in SIGINT mission activities performed at the 
site. The 10 inspectors found an overall lack of 10 documentation and noted the need for 
increased physical protection in mission spaces given NSAT’s open architecture. 
Managing training at a site with significant military presence and ensuring compliance in 
SIGINT activities performed under multiple authorities pose challenges for NSAT 
leadership. 


(II) Field Inspection: 


(U/ /FOUO) During the field inspection of£ 


the 10 (b)(3)-P.L. 86-36 


inspector reviewed 10 program management, tracking of 10 training for site personnel, 
and general awareness of 10 within the workforce. The inspector found that the site had 
not formally documented the 10 program and that IO-related information was not readily 
accessible to site personnel. The OIG recommended that the site establish a web 
presence to provide 10 information. The inspector also found that database accesses 
were not terminated when personnel moved to new assignments. The OIG recommended 
that the Intelligence Oversight Officer verify that database accesses associated with 
previous assignments be terminated. 

(U) Special Study: Assessment of Management Controls Over FAA §702—Revised 
and Reissued 


(u/ /rou ot 


the NSA OIG published a revised report on the results of 


a review of the management controls implemente d to provide reasonable assuranc e of 
compliance with FAA §702. The original report. 


was 


revised for classification discrepancies and because new information had been received 
after release of the original report. The study found that NSA control procedures are 
adequately designed to comply with FAA §702. Eleven recommendations were made for 
improving those controls. 


(b)(3)-P.L. 86-36 


TOP SECRET//SI/TK//NOFORN - 
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• (U) Ongoing Studies 

(U//F OUO) T he following special studies were in progress during the quarter and will be 
summarized in subsequent quarterly reports: 


o 

o 

o 

o 

o 


(U//F©y©) FAA §702 


'(b) (3)-P.L. 86-36 


(Ul 


Auditing Control Framework for Signals Intelligence 


System Queries 


(U) I I System 

(U) Technology Directorate Mission Compliance Program 

(U) Information Assurance Directorate Office of Oversight and Compliance 
Mission Compliance Program 


IV. (U) Notifications 


(U//FOUO) During the first quarter, a number of notifications were provided to Congress. 

including: .. (l) 

__-.. / (b) (3)-P.L. 86-36 

• 1TS//SI//NF) | I NSA notified Congressional intelligence 

committees about an unauthorized disclosure of properly classified national security 
information derived from SIGINT. NSA became aware of this disclosure on 


"(b) (1 >. 

(b)(3)-P.L. 86-36 
(b) (3)-18 USC 798 
(b)(3)-50 USC 3024 


(b)(1) 

(b)(3)-P.L. 86-36 
(b)(3)-50 USC 3024( 



The NSA Office of General Counsel has filed a Crime Report with the 


DOJ on this unauthorized disclosure. 


(SYSI'YRFI TO USA. FVEY) 


NSA notified 


Congressional intelligence committees about a potential retention and dissemination 
comp 1 ian ce incident involving an NSA corporate database designed for long-term 
retention! I 


(T0//QI/NF )[ 


NSA notified Congressional intelligence committees 


about the FlSC’s opinion relating tof 


(b)(1) 

(b)(3)-P.L. 86-36 


TOP SECRET//SI/TK//NOFORN 
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(b)(3)-P.L. 86-36 
(b) (3)-18 USC 798 
(b)(3)-50 USC 3024(i) 
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NSA purged the unauthorized collecti on and recalled all reporting based on those 
communications. | the FISC authorized such collection to be (b)(1) 

undertaken prospectively. (b)(3)-P.L. 86-36 


V. (U) NSA/CSS 10 Program Initiatives 

• ( U//FOUO) As reported in the second quarter CY201I report. NSA/CSS is 

developing a tool to automate submi ssion of mission compliance incident report s 
across the NSA/CSS enterprise. The 


will 


become the Agency’s central tool for reporting potential mission compliance 
incidents and will provide a streamlined management process, a central rep ositor 
and metrics data to support root cause identific ation and trend analysis. Th 
expected to be implemented | | With the im plementation of 

NSA will be able to perform comprehensive trend analysis! 



VI. (U) Other Matters 


(b)(3)-P.L. 86-36 


iring the reporting period. NSA identified two questionable intelligence 
activities of a serious nature and one potential crime, as defined in Directive-Type Memorandum 
08-052. Each activity has been reported to Congress and has been described in Section IV. 

t S//NP )-The NSA OIG has concluded its investig ation into an allegation mentioned in the 
third quarter CY2012 report that activity associated with[~ 


The allegation was unsubstantiated 



(TO 751 '/NFT During the first quarter ofCY2013. the AG was involved in I I instances 
of intelligence-related collection activities associated with USP hostage and detainee cases. 


(b) (1) 

(b)(3)-p. l. 


86-36 


(b) (1) 

(b)(3)-P.L. 86-36 
(b) (3)-50 USC 3024(i) 
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